Windows Event Forwarding and Event Collectors In-Depth

Поділитися
Вставка
  • Опубліковано 26 січ 2025

КОМЕНТАРІ • 10

  • @unatommer
    @unatommer 2 місяці тому

    This was great, it pointed me in the right direction.

  • @golgothus
    @golgothus 3 роки тому

    Absolutely loved this webcast! Plenty of useful information in regards to the benefits of WEF/WEC usage, especially in an environment where you have multiple SIEMS.
    Also, Powershell was mentioned, definitely seems like wecutil will be worth looking into further for automation and scripting purposes!

  • @zikkthegreat
    @zikkthegreat 3 роки тому +4

    is there a link for the followup video on implementing?

  • @peterparker175
    @peterparker175 Рік тому +2

    does anyone have manual how to setup WEC cluster with 2 or 3 servers?

  • @chuck_henry
    @chuck_henry 3 місяці тому

    Will you publish the event filters you recommend somewhere?

  • @daledreher4107
    @daledreher4107 3 роки тому

    Awesome video, very helpful! Justin has the same handwriting as me 😊

  • @chamkadar86
    @chamkadar86 2 роки тому +1

    Can some one please make video on how to configure WEC for workgroup environment with CA server.

  • @avtraveller
    @avtraveller 2 роки тому

    I did similar deployment in our enviroment but WEC is a single point of failure . We tried the windows built in mechanism with 2 virtual servers configured as cluster but didnt work , Any ideas how to mitigate this ?

  • @simple-security
    @simple-security 2 роки тому

    summary:
    don't use wec/wef,
    stick to ARC/AMA agent for servers?
    and log analytics agent for workstations if needed (AMS not supported for workstations)?
    with advanced powershell auditing enabled in group policy?
    plus edr agent for advanced threat detections?

  • @BarryHarrellYouTube
    @BarryHarrellYouTube 2 роки тому +1

    Waste of time. The one guy on the right has a video on this subject and none of his links work. You think that if he teaches he would make sure his links work. But nope - wasted my time.